← Back to TruSec
Privacy Policy
Effective Date: April 6, 2026
1. Introduction
Welcome to TruSec (“we”, “our”, “us”), an AI-powered cybersecurity platform designed to assist security teams with threat intelligence, analysis, and decision-making.
This Privacy Policy explains how we collect, use, disclose, and protect your information when you use:
- TruSec web applications (e.g., https://ask.trusec.io)
- APIs and integrations
- Security Answer Engine and related services
By using TruSec, you agree to the terms outlined in this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide, including:
- Account details (name, email, organization)
- Authentication data (SSO, API keys, tokens)
- Queries submitted to the Security Answer Engine
- Uploaded data (logs, indicators, documents, configs)
- Connector configurations (e.g., VirusTotal, Splunk API keys)
2.2 Automatically Collected Information
We may collect:
- Device and browser metadata (IP address, OS, user agent)
- Usage data (features used, session activity, timestamps)
- Log data (queries, responses, errors)
- Performance and telemetry data
2.3 Third-Party Data
When you use connectors or integrations, we may process data from:
- Threat intelligence platforms (e.g., VirusTotal, Shodan)
- SIEM / security tools
- Cloud platforms or APIs connected by you
3. How We Use Your Information
We use your data to:
- Provide and improve TruSec services
- Generate AI-powered security insights and responses
- Execute queries across connected tools and data sources
- Monitor system performance and detect abuse
- Enhance security, reliability, and accuracy
- Provide customer support
We do not use customer data to train general-purpose AI models unless explicitly agreed.
4. AI Processing & Data Handling
TruSec processes data using AI models to:
- Analyze cybersecurity queries
- Correlate threat intelligence
- Generate responses and recommendations
Key principles:
- Data is processed only to fulfill user requests
- Context is ephemeral by default unless stored explicitly
- Sensitive data handling follows least-privilege principles
- Customers control what data is sent via connectors or prompts
5. Data Sharing and Disclosure
We may share data only in the following cases:
5.1 Service Providers
With trusted vendors for:
- Hosting (cloud infrastructure)
- Logging and observability
- Authentication
5.2 Integrations
When you enable connectors, data may be shared with:
- External APIs you configure (e.g., VirusTotal)
5.3 Legal Requirements
If required by law, regulation, or legal process, data may be shared as appropriate.
6. Data Retention
We retain data based on:
- Account lifecycle
- Operational requirements
Typical retention categories:
- Logs and telemetry: Short-term (e.g., 7–30 days)
- Customer data: Until deleted by user or account termination
- Backups: Retained for disaster recovery purposes
7. Security Measures
We implement strong security controls, including:
- Encryption in transit (TLS) and at rest
- Role-based access control (RBAC)
- Audit logging and monitoring
- Secure API access and authentication
- Isolation between tenant environments
8. Your Rights and Choices
Depending on your jurisdiction, you may have rights to:
- Access your data
- Correct inaccurate data
- Delete your data
- Restrict or object to processing
- Export your data
You can exercise these rights by contacting us at:
info@trusec.io
9. Cookies and Tracking
We may use cookies or similar technologies for:
- Session management
- Authentication
- Analytics and performance monitoring
You can control cookie preferences via your browser settings.
10. International Data Transfers
Your data may be processed in regions where our infrastructure or service providers operate. We ensure appropriate safeguards are in place for cross-border data transfers.
11. Children's Privacy
TruSec is not intended for use by individuals under the age of 18. We do not knowingly collect data from children.
12. Changes to This Privacy Policy
We may update this policy periodically. We will notify users of significant changes via:
- Email notifications
- Platform announcements
13. Contact Us
If you have questions about this Privacy Policy or your data: